VYPR

sisdk-release

by Silabs.com

CVEs (5)

  • CVE-2026-6432MedJun 25, 2026
    risk 0.00cvss epss 0.00

    Improper bounds validation in EmberZNet SDK versions 9.0.2 and earlier may result in crashes or dynamic memory leakage.

  • CVE-2026-4526MedJun 25, 2026
    risk 0.00cvss 6.5epss 0.00

    In EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logic and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was…

  • CVE-2026-47147HigJun 25, 2026
    risk 0.00cvss 7.1epss 0.00

    In EmberZNet v9.0.2 and earlier, malformed OTA requests can drive the OTA server parser into out-of-bounds reads. A limited amount of data from RAM is read back to the requester. The size and location of this data is limited. These requests must come from a device that has…

  • CVE-2026-47145MedJun 25, 2026
    risk 0.00cvss 6.5epss 0.00

    In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a device that has already joined the network. Only devices supporting the Color Control cluster may be impacted.

  • CVE-2026-2815HigJun 25, 2026
    risk 0.00cvss epss 0.00

    Incorrect use of the PUF key for user key generation in EFR32xG27 results in predictable keys